Palo Alto Networks Certified Network Security Administrator (PCNSA)Palo Alto Networks Security PlatformMedium

A network administrator is setting up a Palo Alto Networks firewall and needs to enable communication between two interfaces (e.g., Ethernet1/1 and Ethernet1/2) that are part of the same security zone but belong to different VLANs. The administrator expects traffic to flow between these interfaces without explicit security policy rules, as they are considered 'inside' the same trusted boundary. Which configuration concept facilitates this behavior?

  1. AInter-zone routing
  2. BSecurity Policy rule
  3. CIntra-zone forwarding
  4. DVirtual Router configuration
Show answer & explanation

Correct answer: C. Intra-zone forwarding

Intra-zone forwarding allows traffic to flow between interfaces (or subinterfaces) assigned to the same security zone without requiring an explicit security policy rule. This is because, by definition, traffic within a single zone is considered trusted and implicitly allowed to communicate.

Why the other options are wrong

  • A. Inter-zone routing refers to traffic flowing between different security zones, which always requires a security policy.
  • B. A Security Policy rule is required for inter-zone traffic, but not for intra-zone traffic by default.
  • D. Virtual Router configuration defines routing behavior, but doesn't manage policy rules for intra-zone traffic.

Intra-zone Forwarding

The default behavior in Palo Alto Networks firewalls that allows traffic to flow between interfaces (physical or subinterfaces) assigned to the same security zone without the need for an explicit security policy rule.

  • Traffic within a zone is implicitly trusted.
  • Reduces policy complexity for internal segments.
  • Contrasts with inter-zone traffic, which always requires policy.

Memory trick: Intra-zone is like movement within your own house – no special pass needed.

More Palo Alto Networks Security Platform questions